From 2689eb969889b4f642fae1f7eeaed48a9b836a9d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marvin=20=C3=96hlerking?= Date: Thu, 1 Aug 2024 16:11:18 +0200 Subject: [PATCH] fix csp --- dockerconf/nginx.conf.template | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dockerconf/nginx.conf.template b/dockerconf/nginx.conf.template index b501492..4ab4ca2 100644 --- a/dockerconf/nginx.conf.template +++ b/dockerconf/nginx.conf.template @@ -2,7 +2,7 @@ server { listen 4100; server_name localhost; - set $csp "default-src 'self' ${API_URL}; base-uri 'self'; script-src 'nonce-$request_id' 'strict-dynamic' 'unsafe-inline' https:; object-src 'none'; font-src 'self' data:; img-src 'self' data:; style-src 'self' 'unsafe-inline'; frame-src 'self' https://docs.dbildungscloud.de/"; + set $csp "default-src 'self' ${API_URL}/*; base-uri 'self'; script-src 'nonce-$request_id' 'strict-dynamic' 'unsafe-inline' https:; object-src 'none'; font-src 'self' data:; img-src 'self' data:; style-src 'self' 'unsafe-inline'; frame-src 'self' https://docs.dbildungscloud.de/"; location /status { stub_status;